Skip to content

Hide Navigation Hide TOC

Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb)

Exodus is Android spyware deployed in two distinct stages named Exodus One (dropper) and Exodus Two (payload).(Citation: SWB Exodus March 2019)

Cluster A Galaxy A Cluster B Galaxy B Level
Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware Download New Code at Runtime - T1407 (6c49d50f-494d-4150-b774-a655022d20a6) Attack Pattern 1
Location Tracking - T1430 (99e6295e-741b-4857-b6e5-64989eb039b4) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware Audio Capture - T1429 (6683aa0c-d98a-4f5b-ac57-ca7e9934a760) Attack Pattern 1
Screen Capture - T1513 (73c26732-6422-4081-8b63-6d0ae93d449e) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Data from Local System - T1533 (e1c912a9-e305-434b-9172-8a6ce3ec9c4a) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Archive Collected Data - T1532 (e3b936a4-6321-4172-9114-038a866362ec) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Non-Standard Port - T1509 (948a447c-d783-4ba0-8516-a64140fcacd5) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Call Log - T1636.002 (1d1b1558-c833-482e-aabb-d07ef6eae63d) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
System Network Connections Discovery - T1421 (dd818ea5-adf5-41c7-93b5-f3b839a219fb) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Software Discovery - T1418 (198ce408-1470-45ee-b47f-7056050d4fc2) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Web Protocols - T1437.001 (2282a98b-5049-4f61-9381-55baca7c1add) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
System Network Configuration Discovery - T1422 (d4536441-1bcc-49fa-80ae-a596ed3f7ffd) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Stored Application Data - T1409 (702055ac-4e54-4ae9-9527-e23a38e0b160) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Calendar Entries - T1636.001 (a9fa0d30-a8ff-45bf-922e-7720da0b7922) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware Contact List - T1636.003 (e0b9ecb8-a7d1-43c7-aa30-8e19c6a92c86) Attack Pattern 1
Internet Connection Discovery - T1422.001 (45a5fe76-eda3-4d40-8f22-c186efd6278d) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware Exploitation for Privilege Escalation - T1404 (351c0927-2fc1-4a2c-ad84-cbbee7eb8172) Attack Pattern 1
Video Capture - T1512 (d8940e76-f9c1-4912-bea6-e21c251370b6) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
SMS Messages - T1636.004 (c6421411-ae61-42bb-9098-73fddb315002) Attack Pattern Exodus - S0405 (3049b2f2-e323-4cdb-91cb-13b37b904cbb) Malware 1
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern Call Log - T1636.002 (1d1b1558-c833-482e-aabb-d07ef6eae63d) Attack Pattern 2
Application Layer Protocol - T1437 (6a3f6490-9c44-40de-b059-e5940f246673) Attack Pattern Web Protocols - T1437.001 (2282a98b-5049-4f61-9381-55baca7c1add) Attack Pattern 2
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern Calendar Entries - T1636.001 (a9fa0d30-a8ff-45bf-922e-7720da0b7922) Attack Pattern 2
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern Contact List - T1636.003 (e0b9ecb8-a7d1-43c7-aa30-8e19c6a92c86) Attack Pattern 2
System Network Configuration Discovery - T1422 (d4536441-1bcc-49fa-80ae-a596ed3f7ffd) Attack Pattern Internet Connection Discovery - T1422.001 (45a5fe76-eda3-4d40-8f22-c186efd6278d) Attack Pattern 2
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern SMS Messages - T1636.004 (c6421411-ae61-42bb-9098-73fddb315002) Attack Pattern 2